Buffer overflow in Qt - CVE-2018-19869
Published: May 4, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing SVG images within the qsvghandler.cpp file in Qt. A remote attacker can create a specially crafted image, pass it to he application that uses Qt library for SVG processing, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
qt5-qtbase (Red Hat package)
qt5-qttools (Red Hat package)
qgnomeplatform (Red Hat package)
qt (Red Hat package)
mingw-sip
sip (Red Hat package)
mingw-qt5-qtwebkit
libqt5svg5 (Ubuntu package)
mingw-qt5-qtwebsockets
mingw-qt5-qtxmlpatterns
mingw-qt5-qt3d
mingw-qt5-qtactiveqt
mingw-qt5-qtbase
mingw-qt5-qtcharts
mingw-qt5-qtdeclarative
mingw-qt5-qtgraphicaleffects
mingw-qt5-qtimageformats
mingw-qt5-qtlocation
mingw-qt5-qtmultimedia
mingw-qt5-qtquickcontrols
mingw-qt5-qtscript
mingw-qt5-qtsensors
mingw-qt5-qtserialport
mingw-qt5-qtsvg
mingw-qt5-qttools
mingw-qt5-qttranslations
mingw-qt5-qtwinextras
mingw-python-qt5
qt5-qtxmlpatterns (Red Hat package)
qt5-qtquickcontrols (Red Hat package)
qt5-qtcanvas3d (Red Hat package)
qt5-qtconnectivity (Red Hat package)
qt5-qtdeclarative (Red Hat package)
qt5-qtdoc (Red Hat package)
qt5-qtgraphicaleffects (Red Hat package)
qt5-qtimageformats (Red Hat package)
qt5-qtlocation (Red Hat package)
qt5-qtmultimedia (Red Hat package)
qt5-qtquickcontrols2 (Red Hat package)
qt5-qtscript (Red Hat package)
qt5-qtsensors (Red Hat package)
qt5-qtserialbus (Red Hat package)
qt5-qtserialport (Red Hat package)
qt5-qtsvg (Red Hat package)
qt5-qttranslations (Red Hat package)
qt5-qtwayland (Red Hat package)
qt5-qtwebchannel (Red Hat package)
qt5-qtwebsockets (Red Hat package)
qt5-qtx11extras (Red Hat package)
qt5-qt3d (Red Hat package)
qt5 (Red Hat package)
python-qt5 (Red Hat package)
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for x86_64
SUSE Linux
Opensuse
Ubuntu
Fedora
How to mitigate CVE-2018-19869
qt5-qtbase (Red Hat package) - update to 5.12.5-4.el8
qt5-qttools (Red Hat package) - update to 5.12.5-1.el8
qgnomeplatform (Red Hat package) - update to 0.4-3.el8
qt (Red Hat package) - update to 4.8.7-8.el7
mingw-sip - update to 4.19.13-2.fc29
sip (Red Hat package) - update to 4.19.19-1.el8
mingw-qt5-qtwebkit - update to 5.9.4-0.8.gitbd0657f.fc29
libqt5svg5 (Ubuntu package) - update to 5.9.5-0ubuntu1.1
mingw-qt5-qtwebsockets - update to 5.11.3-1.fc29
mingw-qt5-qtxmlpatterns - update to 5.11.3-1.fc29
mingw-qt5-qt3d - update to 5.11.3-1.fc29
mingw-qt5-qtactiveqt - update to 5.11.3-1.fc29
mingw-qt5-qtbase - update to 5.11.3-1.fc29
mingw-qt5-qtcharts - update to 5.11.3-1.fc29
mingw-qt5-qtdeclarative - update to 5.11.3-1.fc29
mingw-qt5-qtgraphicaleffects - update to 5.11.3-1.fc29
mingw-qt5-qtimageformats - update to 5.11.3-1.fc29
mingw-qt5-qtlocation - update to 5.11.3-1.fc29
mingw-qt5-qtmultimedia - update to 5.11.3-1.fc29
mingw-qt5-qtquickcontrols - update to 5.11.3-1.fc29
mingw-qt5-qtscript - update to 5.11.3-1.fc29
mingw-qt5-qtsensors - update to 5.11.3-1.fc29
mingw-qt5-qtserialport - update to 5.11.3-1.fc29
mingw-qt5-qtsvg - update to 5.11.3-1.fc29
mingw-qt5-qttools - update to 5.11.3-1.fc29
mingw-qt5-qttranslations - update to 5.11.3-1.fc29
mingw-qt5-qtwinextras - update to 5.11.3-1.fc29
mingw-python-qt5 - update to 5.11.3-2.fc29
qt5-qtxmlpatterns (Red Hat package) - update to 5.12.5-1.el8
qt5-qtquickcontrols (Red Hat package) - update to 5.12.5-1.el8
qt5-qtcanvas3d (Red Hat package) - update to 5.12.5-1.el8
qt5-qtconnectivity (Red Hat package) - update to 5.12.5-1.el8
qt5-qtdeclarative (Red Hat package) - update to 5.12.5-1.el8
qt5-qtdoc (Red Hat package) - update to 5.12.5-1.el8
qt5-qtgraphicaleffects (Red Hat package) - update to 5.12.5-1.el8
qt5-qtimageformats (Red Hat package) - update to 5.12.5-1.el8
qt5-qtlocation (Red Hat package) - update to 5.12.5-1.el8
qt5-qtmultimedia (Red Hat package) - update to 5.12.5-1.el8
qt5-qtquickcontrols2 (Red Hat package) - update to 5.12.5-1.el8
qt5-qtscript (Red Hat package) - update to 5.12.5-1.el8
qt5-qtsensors (Red Hat package) - update to 5.12.5-1.el8
qt5-qtserialbus (Red Hat package) - update to 5.12.5-1.el8
qt5-qtserialport (Red Hat package) - update to 5.12.5-1.el8
qt5-qtsvg (Red Hat package) - update to 5.12.5-1.el8
qt5-qttranslations (Red Hat package) - update to 5.12.5-1.el8
qt5-qtwayland (Red Hat package) - update to 5.12.5-1.el8
qt5-qtwebchannel (Red Hat package) - update to 5.12.5-1.el8
qt5-qtwebsockets (Red Hat package) - update to 5.12.5-1.el8
qt5-qtx11extras (Red Hat package) - update to 5.12.5-1.el8
qt5-qt3d (Red Hat package) - update to 5.12.5-2.el8
qt5 (Red Hat package) - update to 5.12.5-3.el8
python-qt5 (Red Hat package) - update to 5.13.1-1.el8
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00008.html
- https://access.redhat.com/errata/RHSA-2019:2135
- https://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/
- https://codereview.qt-project.org/#/c/234142/
- https://lists.debian.org/debian-lts-announce/2019/05/msg00014.html
Related Security Bulletins
- Multiple vulnerabilities in Qt
- Red Hat update for qt5
- OpenSUSE Linux update for libqt5-qtsvg
- OpenSUSE Linux update for libqt4
- OpenSUSE Linux update for libqt4
- OpenSUSE Linux update for libqt4
- OpenSUSE Linux update for libqt4
- Red Hat Enterprise Linux 7 update for qt
- Ubuntu update for qtsvg-opensource-src
- Fedora 29 update for mingw packages